ThreatCluster

Critical Vulnerabilities CVE-2026-79657 and CVE-2026-78568 Disclosed

First seen 26 Aug 2026, 06:53 UTC www.incibe.es 74

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-79657 and CVE-2026-78568, were published on August 25, 2026, with CVSS scores of 9.80 and 9.30 respectively. Both vulnerabilities allow remote access with low complexity and no user interaction required, impacting confidentiality, integrity, and availability. They are categorized as critical due to their potential for severe exploitation. Affected systems include those that utilize the software associated with these CVEs. Security teams are advised to prioritize patching these vulnerabilities immediately. No active exploitation has been confirmed yet, but the high severity warrants urgent attention. The vulnerabilities were disclosed by INCIBE-CERT, indicating a reliable source of information.

Key Points: • CVE-2026-79657 and CVE-2026-78568 have CVSS scores of 9.80 and 9.30, indicating critical severity. • Both vulnerabilities allow remote exploitation with low complexity and no user interaction. • Immediate patching is recommended as both vulnerabilities were disclosed on August 25, 2026.

Timeline

2026-08-25
CVE-2026-79657 published
CVE-2026-79657 disclosed with a CVSS score of 9.80, allowing remote access with low complexity.
Article 1
2026-08-25
CVE-2026-78568 published
CVE-2026-78568 disclosed with a CVSS score of 9.30, enabling remote exploitation without user interaction.
Article 2
2026-08-26
Advisory issued
INCIBE-CERT issued advisories for both vulnerabilities, urging immediate action from affected organizations.
Article 1